Repository navigation
fix(ci): install a pinned wasm-opt instead of apt, and bound the wasm jobs - #2314
Merged
Merged
Conversation
… jobs `apt-get update && apt-get install -y binaryen` stalled indefinitely on two separate `main` runs (32170059933 on 136f11b, 32218864077 on 986bfc7). The step normally takes ~10 seconds. With no `timeout-minutes` on the job, each stall ran to GitHub's 6-hour ceiling and took the whole CI run down as `cancelled` — `main` went red twice for an apt mirror problem unrelated to any diff. `publish-wasm.yml` carried the same call, where a stall would have held a release the same way. Both workflows now install wasm-opt through `scripts/install-binaryen.sh`: - No apt. The binaryen release archive is fetched with explicit connect/total timeouts and retries, so a stalled mirror fails in minutes. - Version pinned, so `wasm-opt -Oz` output no longer depends on whichever binaryen the runner image's Ubuntu carries. That artifact ships to npm. - SHA-256 pinned. Binaryen publishes no signature or checksum file, so this is the only integrity check standing between a tampered release asset and a published wasm bundle. - Extracts `bin/wasm-opt` only — it is statically linked, so 19 MB of the 102 MB archive is all that is needed. Both jobs also gain `timeout-minutes: 30`, so a future stall of any kind fails fast and re-runnable rather than burning a runner for six hours. `test_web_ci_exercises_release_wasm_optimization` pinned the old apt string; it now asserts CI and the release install wasm-opt through the same script, which also catches the two workflows drifting apart. Two new tests guard the properties the fix has to keep: no apt-installed binaryen, bounded download, pinned version + checksum, and a timeout on both wasm build jobs. All three were mutation-checked to fail when the fix is reverted.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | 0914c03 | Commit Preview URL Branch Preview URL |
Aug 19 2026, 09:30 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
The
WASM web packagejob no longer installs binaryen from apt. Both it andpublish-wasm.yml'sbuild-wasmgo through a newscripts/install-binaryen.sh, which fetches a version-pinned,SHA-256-verified binaryen release archive with explicit connect/total
timeouts and retries, and extracts
bin/wasm-optonly (it is staticallylinked, so 19 MB of the 102 MB archive is all that is needed).
Both jobs also gain
timeout-minutes: 30.Three things improve beyond unblocking CI:
wasm-opt -Ozoutput becomes reproducible. It previously trackedwhichever binaryen the runner image's Ubuntu happened to carry. That binary
optimizes the artifact published to npm.
checksum file for its release assets, so the pinned SHA-256 is the only thing
between a tampered asset and a published wasm bundle.
tool, since there is now one script instead of two copies of a shell line.
Why
apt-get update && apt-get install -y binaryenstalled indefinitely on twoseparate
mainruns:136f11b3cancelled986bfc7That step's healthy duration is 9–14 seconds:
So
mainwent red twice for an apt mirror stall unrelated to any diff, andeach time it held a runner for six hours. Two independent faults made that
possible — an unbounded network install, and no
timeout-minuteson the job(
ci.ymlhas none on any job, while every other workflow in this repo setsthem). This fixes both for the affected jobs.
publish-wasm.ymlcarried the identical apt call, so the same stall would havesilently held a release for six hours.
Before / After
Before — unpinned, unbounded, duplicated in two workflows:
After — one script, pinned and bounded:
Verified locally that the installed binary accepts the exact flag set
crates/bashkit-wasm/scripts/build.shpasses(
-Oz --enable-bulk-memory --enable-nontrapping-float-to-int --enable-sign-ext),and that re-running the script is idempotent.
mainis green again on the re-run of the cancelled job(32218864077 attempt 2),
so this PR is the durable fix rather than the unblock.
Tests.
test_web_ci_exercises_release_wasm_optimizationasserted the literalstring
apt-get install -y binaryen, so it had to change; it now asserts CI andthe release install through the same script, which is a stronger invariant than
the string it replaced. Two new tests guard what the fix must keep — no
apt-installed binaryen, a bounded download, a pinned version and checksum, and a
timeout on both wasm build jobs. Each was mutation-checked:
Risk
script, and its tests.
than degrading — which is the intent. Bumping means editing version and
checksum together in one file.
build.shstill treatswasm-optas optional and skips-Ozwhen it isabsent, so local builds without the tool are unaffected.
ci.ymljobs still carry notimeout-minutes. Only these two demonstrated a hang, so I scoped the changeto them rather than picking values for jobs I have no timing evidence for.
Worth a follow-up.
Checklist
wasm-optstays optional for localbuilds; no consumer-visible change
Generated by Claude Code